Skip to content

kernel CVE-2021-23133

Moderate
tjkirch published GHSA-x849-g985-wxr9 Jun 25, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.1.2

Patched versions

1.1.2

Description

A use-after-free flaw was found in the Linux kernel's SCTP socket functionality that triggers a race condition. This flaw allows a local user to escalate their privileges on the system.

Severity

Moderate

CVE ID

CVE-2021-23133

Weaknesses

No CWEs